Skip to content

fix(tcloud-release): wait for npm publication processing - #64

Merged
drewstone merged 1 commit into
mainfrom
fix/tcloud-npm-processing-window-20260930
Sep 30, 2026
Merged

drewstone merged 1 commit into
mainfrom
fix/tcloud-npm-processing-window-20260930

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Problem

npm accepted TCloud 0.8.0 and signed its provenance in run 36671321028, attempt 1. npm said processing could take a few minutes. The verifier stopped after six checks and five ten-second waits. The package appeared later; attempt 2 succeeded.

Change

Extend the existing loop to 31 reads and 30 ten-second waits. Exact hash checks, existing-version behavior and trusted publishing are unchanged. No version or access changes.

Evidence

  • The exact maintained publication step verified public TCloud 0.8.0 against the reviewed candidate: SHA1 6284f2620e94bcb377e5fe158f5c19db0cee26a2.
  • Public tarball matches the reviewed candidate byte for byte: SHA256 2b946cf008817b1bcc49c2ebdb50d70d73824320ede8773ea74b046eef22fefe.
  • YAML parsing, Bash syntax, all eight existing script checks and normal commit/push hooks passed.
  • Independent review approved the exact three-line diff over 945d452dac715ae38da6822465ee6b40ff9d58d8: 31 checks, 300 seconds of retry waits, with unchanged rejection of different bytes.
  • Publication run is terminal success on attempt 2.

Risk and recovery

A missing package takes longer to fail verification. Different package bytes still fail immediately. Reverting restores the old wait limit.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 2ec3a2a0

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-30T05:20:25Z

@drewstone

Copy link
Copy Markdown
Contributor Author

Independent cohort reviewer approved the exact three-line diff at 2ec3a2a over 945d452. The existing loop makes 31 checks with 30 ten-second waits; mismatched bytes still fail immediately and publisher authorization is unchanged. YAML parsing, Bash syntax, the exact maintained public-registry verifier, eight script cases, normal hooks and current SDK CI all passed.

@drewstone
drewstone merged commit b9f74e3 into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants